Atlas / MCP servers / noditlabs / Nodit

NoditBLOCK

mcp/noditlabs/nodit

A Model Context Protocol (MCP) server for AI agents to interact with blockchain data via Nodit’s Web3 Data and Node APIs. Enables LLMs to access structured, multi-chain blockchain context with zero blockchain-specific logic.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
8 8r · 0w · 0d
Transport
stdio
License
Apache-2.0
Stars
23
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that connects AI agents and developers to structured, context-ready blockchain data across multiple networks through Nodit's Web3 infrastructure.

[](https://opensource.org/licenses/Apache-2.0) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://smithery.ai/server/@noditlabs/nodit-mcp-server)

Overview

Nodit MCP Server simplifies how AI models and applications interact with blockchain ecosystems. Instead of handling complex node RPCs, raw event logs, or chain-specific data structures, developers can access normalized, multi-chain blockchain data in a format optimized for AI reasoning and decision-making.

With Nodit's MCP, you can:

  • Build AI agents that query, analyze, and act on real-time blockchain data across EVM-compatible and non-EVM networks.
  • Develope Web3-integrated applications without requiring specialized blockchain development expertise.
  • Leverage Nodit's reliable node infrastructure, Web3 Data APIs, and GraphQL indexing services through a unified access layer.
  • Easily develop with blockchain MCP in both local and remote integration, depending on your workflow needs.

Supported networks include Ethereum, Base, Optimism, Arbitrum, Polygon, Aptos, Bitcoin, Dogecoin, TRON, XRPL, GIWA(Sepolia) and more.

Table of Contents

  • List of Tools
  • Features
  • Prerequisites
  • [Running Local Nodit MCP Server](#running-local-nodit-mcp-s
Read from source at commit 57aed7f90edcOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add nodit-mcp-server --env NODIT_API_KEY=${NODIT_API_KEY} -- npx -y @noditlabs/[email protected]
claude-desktop
{
  "mcpServers": {
    "nodit-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@noditlabs/[email protected]"
      ],
      "env": {
        "NODIT_API_KEY": "${NODIT_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
call_nodit_apiread
call_nodit_aptos_indexer_apiread
get_nodit_api_specread
get_nodit_aptos_indexer_api_specread
list_nodit_api_categoriesread
list_nodit_aptos_indexer_api_query_rootread
list_nodit_data_apisread
list_nodit_node_apisread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/helper/nodit-apidoc-helper.ts:354
return yaml.load(fileContents);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, js-yaml, zod, @types/js-yaml, @types/node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:283
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 57aed7f90edcfull audit observations/trust-audit/mcp-server/noditlabs__nodit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0957aed7f90edcBLOCKD69first audit
06

Questions

What is the Nodit MCP server?

A Model Context Protocol (MCP) server for AI agents to interact with blockchain data via Nodit’s Web3 Data and Node APIs. Enables LLMs to access structured, multi-chain blockchain context with zero blockchain-specific logic.

What tools does Nodit expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Nodit safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Nodit need?

It reads NODIT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Nodit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @noditlabs/nodit-mcp-server at 1.2.1.

How current is this page?

The grade is for one exact copy of the source (57aed7f90edc), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement